Sub-Processors

Cognethics engages the third parties listed below to deliver the platform. The registry is maintained by compliance ops and published live — every add, edit, or retirement appears in the RSS change-feed within seconds.

4 active sub-processors · Last refreshed: July 7, 2026

Live registry

ProviderRolePurposeData categoryLocationContractEffective from
Amazon Web ServicesInfrastructureCompute, storage, database, networking, and managed security (CloudTrail, KMS, GuardDuty, Security Hub, VPC Flow Logs). Sensitive application data is encrypted with a dedicated per-tenant AWS KMS customer-managed key (CMK).
  • all customer data (encrypted at rest)
  • operational logs
  • encryption key material (per-tenant customer-managed keys)
  • infrastructure telemetry
AWS region and availability zone selected by the customer (any AWS region), with a cross-region hot standbyDPA + BAA · BAA signed · DPA2024-01-01
AnthropicLLM ProviderLarge language model inference for AI features (summaries, classifications, generation, agent reasoning). Accessed via Anthropic API directly and via AWS Bedrock.
  • user prompts
  • document content for AI processing
Anthropic (US) and AWS Bedrock (US regions)Data Processing Agreement · BAA signed · DPA2024-01-01
CloudflareCDN / EdgeEdge CDN, DDoS protection, and Cloudflare Tunnel routing for *.cognethics.com.
  • request metadata (IP, timestamp, User-Agent, referrer)
Global edge networkData Processing Agreement · DPA2024-01-01
Google (Gemini API)LLM ProviderLarge language model inference for specific workflows including healthcare EOB extraction, denial analysis, technical specification extraction, and invoice parsing.
  • document content for AI processing
  • extracted structured data
Google (US regions)Data Processing Agreement · DPA2024-06-01

Data processing details

Amazon Web Services (AWS)

Region: AWS region and availability zone selected by the customer (any AWS region), with a cross-region hot standby for regional disaster recovery Services used:

  • EC2 (compute)
  • RDS / PostgreSQL (database, AWS BAA signed)
  • EBS (storage, encrypted)
  • VPC (networking, isolated)
  • IAM (access control)
  • CloudTrail (audit logging)
  • KMS (encryption, auto-rotation enabled)
  • GuardDuty (threat detection)
  • Security Hub (compliance monitoring)
  • VPC Flow Logs (network logging)

BAA status: Signed via AWS Artifact Encryption: All data encrypted at rest via AWS KMS, with a dedicated per-tenant customer-managed key (CMK) for sensitive application data, and in transit (TLS 1.2+) Compliance: HIPAA-compatible infrastructure; subject to AWS BAA


Anthropic

Service: Large language models (LLM) Use case: Primary LLM for AI features (summaries, classifications, generation, agent reasoning) Data sent: User prompts, document content (encrypted in transit) Access pattern: Anthropic API directly and via AWS Bedrock Contract: Anthropic commercial terms; Bedrock traffic covered under the AWS BAA


Google (Gemini API)

Service: Large language models (LLM) — Gemini family Use case: Narrow extraction workflows — healthcare EOB extraction and denial analysis, parts technical specification extraction, invoice parsing Data sent: Document content for extraction, structured output (encrypted in transit) Contract: Google Cloud Data Processing Addendum


Cloudflare

Service: CDN, DDoS protection, request routing Data sent: Request metadata only (IP address, timestamp, User-Agent, referrer) No access to: Customer data, documents, database content Purpose: Performance, security, availability


How we notify you of changes

The sub-processor list is a live registry — every add, edit, and retirement is published the moment it lands in the registry.

  • RSS — subscribe to /trust/sub-processors/feed.xml in any reader (Feedly, Inoreader, NetNewsWire) to get every change pushed to you.
  • JSON API — fetch GET /api/v1/core/sub-processors/ for the machine-readable list (public, no auth required). Use the updated_at field on each row to drive your own diff tooling.
  • Email — for customers who prefer email, use the contact form under Requesting more information below, select the Security topic, and ask to be added to the change-notification mailing list.

Every change carries a change_log_entry describing what changed and why, so subscribers can review impact without reading code.


Requesting more information

Pick the matching topic below and we'll route your request to the right team:

  • Sub-processor audit reports or certifications — Security topic
  • Sub-processor DPA or BAA details — Legal topic
  • Data-handling practices — Privacy topic

Request sub-processor information

Pick a topic and we'll route your message to the right team.